2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-58289MEDIUM5.4Microweber 2.0.15 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject mal...
CVE-2024-58288HIGH8.7Genexus Protection Server 9.7.2.10 contains an unquoted service path vulnerability in the protsrvservice Windows service...
CVE-2024-58287HIGH8.8reNgine 2.2.0 contains a command injection vulnerability in the nmap_cmd parameter of scan engine configuration that all...
CVE-2024-58286CRITICAL9.3dizqueTV 1.5.3 contains a remote code execution vulnerability that allows attackers to inject arbitrary commands through...
CVE-2024-42197MEDIUM5.5HCL Workload Scheduler stores user credentials in plain text which can be read by a local user.
CVE-2024-8273HIGH8.8Authentication Bypass by Spoofing vulnerability in HYPR Server allows Identity Spoofing.This issue affects Server: befor...
CVE-2024-40593MEDIUM4.4A key management errors vulnerability in Fortinet FortiAnalyzer 7.4.0 through 7.4.2, FortiAnalyzer 7.2.0 through 7.2.5, ...
CVE-2024-58285MEDIUM5.4Chyrp 2.5.2 contains a stored cross-site scripting vulnerability that allows authenticated users to inject malicious scr...
CVE-2024-58284HIGH7.2PopojiCMS 2.0.1 contains an authenticated remote command execution vulnerability that allows administrative users to inj...
CVE-2024-58283HIGH8.8WBCE CMS version 1.6.2 contains a remote code execution vulnerability that allows authenticated attackers to upload mali...
CVE-2024-58282HIGH7.2Serendipity 2.5.0 contains a remote code execution vulnerability that allows authenticated administrators to upload mali...
CVE-2024-58281HIGH8.8Dotclear 2.29 contains a remote code execution vulnerability that allows authenticated attackers to upload malicious PHP...
CVE-2024-58280HIGH8.8CMSimple 5.15 contains a remote command execution vulnerability that allows authenticated attackers to modify file exten...
CVE-2024-58279HIGH8.8appRain CMF 4.0.5 contains an authenticated remote code execution vulnerability that allows administrative users to uplo...
CVE-2024-2105MEDIUM6.5An unauthorised attacker within bluetooth range may use an improper validation during the BLE connection request to dead...
CVE-2024-2104HIGH8.8Due to improper BLE security configurations on the device's GATT server, an adjacent unauthenticated attacker can read a...
CVE-2024-47570MEDIUM6.6An insertion of sensitive information into log file vulnerability [CWE-532] in FortiOS 7.4.0 through 7.4.3, 7.2.0 throug...
CVE-2024-56840HIGH7.5A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.17.0), RUGGEDCOM ROX MX5000RE (All versio...
CVE-2024-56839HIGH8.6A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.17.0), RUGGEDCOM ROX MX5000RE (All versio...
CVE-2024-56838HIGH8.6A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.17.0), RUGGEDCOM ROX MX5000RE (All versio...
CVE-2024-56837HIGH8.6A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.17.0), RUGGEDCOM ROX MX5000RE (All versio...
CVE-2024-56836HIGH8.8A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.17.0), RUGGEDCOM ROX MX5000RE (All versio...
CVE-2024-56835HIGH8.8A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.17.0), RUGGEDCOM ROX MX5000RE (All versio...
CVE-2024-56464LOW2.7IBM QRadar SIEM 7.5 - 7.5.0 UP14 IF01 is affected by an information disclosure vulnerability involving exposure of direc...
CVE-2024-38798MEDIUM5.8EDK2 contains a vulnerability in BIOS where an attacker may cause “Exposure of Sensitive Information to an Unauthorized ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now